793,143open jobs
50,545companies
124,108added this week
Browse all
Salary
$130k – $153k per year
Location
In office (Boston)
Seniority
Senior · 5+ years exp

Confirmed on the employer's own hiring board on Sep 26, 2026. First seen by Alion on Jul 15, 2026. Charles River Associates scores C on the Alion truth index.

Overview
Company
Impact
Profile match
Charles River Associates (CRA International, Inc.) is a global economic, financial, and strategic management consulting enterprise. The company focuses on providing expert testimony, litigation support, antitrust economics, financial valuation, intellectual property strategy, forensic investigations, and corporate strategy consulting for complex legal, regulatory, and business decisions. Headquartered in Boston, Massachusetts, it operates more than 20 offices across North America, Europe, Asia-Pacific, and South America, serving major law firms, global corporations, accounting firms, and government agencies worldwide.

About Charles River Associates

Charles River Associates is a leading global consulting firm that provides economic, financial, and business management expertise to major law firms, corporations and governments around the world. CRA advises clients on economic and financial matters pertaining to litigation and regulatory proceedings, and guides corporations through critical business strategy and performance-related issues. Since 1965, clients have engaged CRA for its combination of industry experience and rigorous, fact-based analysis that provide clients with clear, implementable solutions to complex business concerns.

Position Overview

CRA is seeking a Cybersecurity Consultant (Assessments / Due Diligence / Advisory) to support client engagements focused on evaluating and managing cybersecurity risk. In this role, you will lead and participate in client-facing assessments, including interviews, workshops, and executive readouts, while operating with a high degree of independence and confidence.

You will be responsible for translating client discussions into clearly defined engagement scopes and Statements of Work (SOWs), aligning deliverables with frameworks such as the NIST CSF and transaction-specific objectives.  This includes the ability to assess cybersecurity posture in transaction and investment contexts, distinguish material risks from broader program maturity gaps, and tailor findings to the needs of private equity, legal, and executive stakeholders. The role includes executing cyber due diligence and proactive security assessments through documentation review, stakeholder interviews, and control evaluation. The role may also support incident readiness reviews, tabletop exercises, and broader cyber resilience assessments to help clients evaluate preparedness, decision-making, and recovery capabilities before or after a cyber event. The role will also work closely with CRA’s incident response team to identify recurring risk themes and control gaps from active and recently closed matters, and help translate those observations into follow-on proactive engagements including gap assessments, tabletop exercises, resilience reviews, and broader security uplift efforts.

This position requires producing high-quality, client-ready reports that include prioritized findings, risk-based recommendations, and executive-level summaries. You will also support senior team members in proposal development and business development efforts, while bridging technical cybersecurity findings into clear business risk narratives for legal, private equity, and executive audiences. You will also contribute to the development of repeatable assessment methodologies, templates, and client-facing deliverables across CRA’s proactive cybersecurity service offerings.

The ideal candidate demonstrates a strong advisory mindset, the ability to independently manage client conversations, and the capability to connect multiple cybersecurity domains-including identity and access management, endpoint security, vulnerability management, backup and recovery, email security, and asset management-into a cohesive and defensible security program assessment. The ideal candidate should also be able to translate technical observations into clear business, legal, and transaction-oriented risk narratives for executive and client stakeholders.

Desired Qualifications

  • Experience:
    • Approximately 5-7 years of experience in cybersecurity consulting, advisory, or due diligence
    • Experience supporting cyber resilience assessments, incident readiness reviews, tabletop exercises, or related preparedness-focused engagements is a plus.
    • Experience collaborating with incident response, forensic, or crisis management teams to translate post-incident observations into proactive assessment, readiness, or remediation-focused engagements is a plus.
  • Client Presence & Communication:
    • Comfortable leading discussions with CIOs, IT Directors, and legal stakeholders
    • Strong ability to guide conversations, ask structured questions, and manage meetings effectively
    • Excellent executive communication skills with clear, concise, and unambiguous delivery
  • Scoping & Advisory Skills:
    • Experience drafting or contributing to Statements of Work (SOWs), engagement letters, and proposals
    • Ability to translate loosely defined client needs into structured deliverables and timelines
    • Strong commercial awareness, including understanding scope boundaries and identifying opportunities to expand engagements
    • Ability to tailor scopes and findings to transaction, diligence, or investment-focused objectives, including identifying issues that are likely to be material to legal, private equity, or executive decision-makers.
  • Report Writing:
    • Impeccable written communication skills, including grammar, structure, and formatting
    • Ability to produce logically consistent, defensible findings and recommendations
    • Experience delivering polished, client-ready cybersecurity risk reports
    • Ability to prioritize findings based on business impact, articulate critical versus lower-priority issues, and develop executive-ready narratives that support practical decision-making.
  • Cybersecurity Frameworks:
    • Strong working knowledge of:
      • NIST Cybersecurity Framework (primary)
      • Supporting frameworks such as CIS Benchmarks, ISO 27001, SOC 2 Type II, HIPAA, and HITRUST
    • Ability to map controls, identify gaps, and translate findings into business risk and impact
    • Ability to evaluate how controls operate together across governance, identity, endpoint, cloud, recovery, and monitoring layers as part of a broader security program or resilience assessment.
  • Technical & Domain Knowledge:
    • Broad understanding of core cybersecurity domains, including:
      • Identity & Access Management (e.g., Active Directory, Entra ID)
      • Endpoint security (e.g., EDR/MDR solutions such as CrowdStrike)
      • Vulnerability management tools (e.g., Tenable, Qualys)
      • Backup and recovery strategies (RTO/RPO, immutability)
      • Email security (phishing protection, DMARC, MFA)
      • Asset inventory, device management, and patch lifecycle practices
      • Comfort reviewing supporting documentation such as security policies and standards, architecture diagrams, control evidence, recovery procedures, and technical configurations in order to assess design and operating effectiveness.
    • Ability to connect these domains into a comprehensive security program narrative
  • Tooling Familiarity (Preferred):
    • Exposure to tools such as CrowdStrike, Tanium, Microsoft 365, Azure/Entra ID, and AWS.
    • Ability to evaluate and interpret tooling deployment, configuration, and coverage in an advisory context rather than operate as a dedicated implementation engineer.
  • Additional Qualifications:
    • Strong organizational and time management skills, with the ability to manage multiple workstreams simultaneously
    • High level of ownership, attention to detail, and ability to deliver work independently with minimal oversight
    • Ability to help develop reusable assessment content, templates, and client-ready materials that support scalable proactive service delivery across multiple engagement types.
  • Nice-to-Have:
    • Certifications such as CISSP, CISM, CISA, PMP, or similar

To Apply

To be considered for a position in the United States or Canada, we require the following:

  • Resume - please include current address, personal email and telephone number;
  • Cover letter - please describe your interest in CRA and how this role matches your goals.

If you are interested in applying for one of our international locations, please visit our Careers site to view and apply for available jobs.

Career Growth and Benefits 

  • CRA’s robust skills development programs, including a commitment to offering 100 hours of training annually through formal and informal programs, encourage you to thrive as an individual and team member. Beginning with research and analysis skill building, training continues with technical training, presentation skills, internal seminars, and career mentoring and performance coaching from an assigned senior colleague. Additional leadership and collaboration opportunities exist through internal firm development activities.
  • We offer a comprehensive total rewards program including a superior benefits package, wellness programming to support physical, mental, emotional and financial well-being, and in-house immigration support for foreign nationals and international business travelers.

Work Location Flexibility

CRA creates a work environment that enables our colleagues to benefit from being together in the office to best deliver on our promise of career growth, mentorship and inclusivity. At the same time, we recognize that individuals realize a range of benefits when working from home periodically. We currently expect that individuals spend at least 3 to 4 days a week working in the office (which may include traveling to another CRA office or to client meetings), with specific days determined in coordination with your practice or team.

Our Commitment to Equal Employment Opportunity

Charles River Associates is an equal opportunity employer (EOE). All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, status as a protected veteran, or any other protected characteristic under applicable law.

Salary and other compensation

A good-faith estimate of the annual base salary range for this position is $130,000 - $152,500. Starting pay within this range may vary based on factors such as education level, experience, skills, geographic location, market conditions, and other qualifications of the successful candidate. This position may be eligible for additional bonus incentive compensation. CRA offers a comprehensive benefits package, subject to eligibility requirements, which may include: medical, dental, and vision insurance; 401(k) retirement plan with employer match; life and disability insurance; paid time off (vacation, sick leave, holidays); paid parental leave; wellness programs and employee assistance resources; and commuter benefits.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
793,143 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Boston
$167k – $213k per year • Equity • In office • Full-Time • 4+ years exp • Bachelor's Degree • San Francisco
DevOps
AWS
Apply
$159k – $202k per year • Equity • In office • Full-Time • 4+ years exp • Boston
Python
JavaScript
Ruby
C#
C++
C#
.NET
DevOps
AWS
Cybersecurity
Threat Modeling
Apply
$134k – $179k per year • Equity • In office • Full-Time • New York
Python
JavaScript
SQL
Bash
AI/ML
CoreWeave
Red Teaming
Machine Learning
DevOps
Splunk
Kubernetes
eBPF
Linux
Cybersecurity
Cyber Kill Chain
Apply
≈ $80k – $155k per year (Estimated) • Remote (United States) • Full-Time • 2+ years exp • Bachelor's Degree • United States
Management
SharePoint
Microsoft Office
Apply
$146k – $205k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Washington
Python
Java
AI/ML
AI Agents
LLM
Machine Learning
DevOps
GitHub Actions
CI/CD
Jenkins
Spinnaker
Shift-Left
Cybersecurity
Qualys Cloud Platform
Wiz
Shift-Left Security
Threat Modeling
OWASP
Apply
≈ $78k – $166k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Ottawa • Vancouver
DevOps
Incident Management
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
SOC 2
GDPR
HIPAA
Threat Modeling
Apply
≈ $83k – $161k per year (Estimated) • Remote (United States) • Full-Time • 4+ years exp • Bachelor's Degree • United States
Cybersecurity
Crowdstrike
SentinelOne
Microsoft Defender
NIST CSF
Sophos
Management
Google Workspace
Apply
≈ $28k – $62k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Bengaluru
Python
Ruby
PowerShell
Perl
Databases
MySQL
Db2
Oracle
Cassandra
MS SQL
AI/ML
Hadoop
Spark
Apache TVM
DevOps
Splunk
Azure
CI/CD
AWS
Linux
Windows
Unix
TCP/IP
DNS
Cybersecurity
Qualys Cloud Platform
ISO 27001
MITRE ATT&CK
NIST CSF
CIS Benchmarks
CVSS
Exabeam
PKI
SIEM
DLP
OWASP
IoT
Matter
Management
Agile
Apply
$89k – $95k per year • In office • Cambridge
Cybersecurity
ISO 27001
NIST CSF
GDPR
Apply
Security Engineer 1 day ago
≈ $15k – $35k per year (Estimated) • Hybrid • Full-Time • 4+ years exp • Associate's Degree • Makati
Python
PowerShell
Cybersecurity
NIST CSF
SIEM
Management
Microsoft Office
Apply
$93k – $100k per year • In office • 1+ year exp • Boston
Analytics
Microsoft Excel
Apply
$100k – $127k per year • In office • 3+ years exp • Boston
Analytics
Microsoft Excel
Apply
$60k – $74k per year • In office • Internship • Bachelor's Degree • Boston
Python
C#
Databases
MS SQL
Apply
$93k – $100k per year • In office • Bachelor's Degree • Boston
Python
C#
Databases
MS SQL
Apply
$175k – $250k per year • In office • 10+ years exp • Bachelor's Degree • Boston
DevOps
Windows
TCP/IP
Cybersecurity
ISO 27001
NIST CSF
SOC 2
HIPAA
Apply
$140k – $200k per year • Remote (United States) • Full-Time • 1+ year exp • Boston
Apply
$50k – $60k per year • In office • Part-Time • Boston
Apply
≈ $139k – $257k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Boston
Management
Agile
Apply
≈ $75k – $187k per year (Estimated) • Equity 3–3% • Remote (United States) • Contractor • Master's Degree • Boston
Design
SolidWorks
Fusion 360
Apply
$186k – $205k per year • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Boston
Java
COBOL
Java
Maven
COBOL
IBM MQ
Databases
MySQL
Apache Kafka
DevOps
CI/CD
Jenkins
AWS
GitHub
Linux
TCP/IP
Management
Agile
Apply
See all jobs
This is one of many
793,143 more open roles from verified company boards, updated every day.